nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #93

Refer to the exhibit. FortiGate is showing continuous high CPU usage. During a maintenance window the CLI command diagnose sys top displays the output shown in the exhibit. The CLI command diagnose…

The correct answer is C. Disable IPS on internal-to-internal policies. By turning off IPS inspection on purely internal traffic you immediately remove that load from the ipsengine daemon and drop CPU usage - no need to wait for signature tweaks or engine restarts.

Performance and Resource Optimization

Question

Refer to the exhibit. FortiGate is showing continuous high CPU usage. During a maintenance window the CLI command diagnose sys top displays the output shown in the exhibit. The CLI command diagnose test application ipsmonitor 5 was run but the CPU usage by daemon ipsengine did not drop. What immediate action can you take to reduce the CPU usage effectively?

Exhibit

FCSS_NST_SE-7.4 question #93 exhibit

Options

  • AMonitor if there is a traffic surge.
  • BRestart all IPS engines.
  • CDisable IPS on internal-to-internal policies.
  • DReview the IPS signatures enabled on the active IPS profiles.

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    76% (32)
  • D
    14% (6)

Explanation

By turning off IPS inspection on purely internal traffic you immediately remove that load from the ipsengine daemon and drop CPU usage - no need to wait for signature tweaks or engine restarts.

Topics

#IPS engine#CPU usage#ipsmonitor#performance tuning

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice